---
id: CVE-2026-19445
title: |-
  A remote, unauthenticated TLS client can make a server crash or call
  through a freed pointer if its sni_callback assigns a different context to
  SSLSocket.context (the documented way to select a certificate per server
  name) and nothing el…
summary: |-
  A remote, unauthenticated TLS client can make a server crash or call
  through a freed pointer if its sni_callback assigns a different context to
  SSLSocket.context (the documented way to select a certificate per server
  name) and nothing el…
severity: critical
cvss: 9.2
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-416
vendor: Python Software Foundation
product: CPython
affected:
  - CPython < 3.16.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:16:40.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19445'
references:
  - url: 'https://github.com/python/cpython/issues/156293'
    label: cna@python.org
  - url: 'https://github.com/python/cpython/pull/158504'
    label: cna@python.org
  - url: >-
      https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/
    label: cna@python.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/30/17'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-30T17:13:20.841Z'
---

## Overview

A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.


Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
